LightRAG Critical Auth Bypass Vulnerability
A hardcoded secret in LightRAG allows unauthenticated attackers to bypass API key protections and gain full control over document operations.
30 results for “sec”
A hardcoded secret in LightRAG allows unauthenticated attackers to bypass API key protections and gain full control over document operations.
A critical vulnerability in Oracle E-Business Suite led to the exposure of personal data at the global cosmetics firm.
Startup Natural secures $30 million to build financial infrastructure specifically for the autonomous agent economy.
Researchers detail how malicious GPU workloads could trigger cascading power grid failures through high-frequency electrical modulation.
Proposed laws targeting anonymous crawlers could undermine digital research, privacy, and cybersecurity efforts across the open web.
Researchers uncovered an exposed server revealing how attackers use AI to industrialize the creation of malware delivery campaigns.
The American-Israeli startup steps out of stealth with significant backing to manage agentic software risks within enterprises.
A sophisticated crypter service is leveraging process ghosting and kernel-driver abuse to cloak various commodity malware strains.
The infrastructure startup aims to challenge Nvidia’s dominance by automating low-level code generation for various AI chip architectures.
A cyberattack on the billing software provider has resulted in the theft of employee, customer, and partner records.
Security leaders are shifting from traditional risk management toward proactive business enablement as AI adoption accelerates.
Internal datasets and service credentials were compromised as attackers utilized a malicious dataset to gain unauthorized access.
An autonomous AI agent framework successfully breached internal Hugging Face infrastructure, marking a shift in attacker tactics.
Intelligence agencies report that Russian actors are hijacking IP cameras to monitor military movements across Europe and Ukraine.
As ransomware groups adopt corporate-style tactics, victims face mounting pressure to decide between recovery risks and total data loss.
A new index aims to standardize how we monitor material cyber incidents by prioritizing verifiable data over industry-wide estimates.
The agentic threat actor JadePuffer is using a new ransomware variant specifically engineered to destroy critical AI model assets.
A third-party platform compromise has led to the unauthorized access of client tax documents at Ernst & Young.
A rivalry between major threat actors is escalating, with data showing a surge in attacks targeting small businesses and large enterprises.
A third-party IT management tool used by Ernst & Young was compromised, leading to the unauthorized exfiltration of tax documents.
Microsoft has deployed emergency updates for Windows 11 to resolve hardware conflicts triggering unexpected power-downs on Dell systems.
The financial giant is open-sourcing its AI-powered security tool to help address software vulnerabilities at the code level.
Enterprise AI systems face active exploitation of a high-complexity remote code execution flaw following a recent patch release.
A critical heap buffer overflow in NGINX puts remote code execution within reach, bypassing common defensive assumptions.
A pair of newly identified vulnerabilities dubbed WP2Shell are being actively exploited in the wild, triggering forced site updates.
Anthropic's frontier AI is changing vulnerability discovery, forcing a rapid shift in how organizations prioritize defense.
Third-party AI integrations evolve too quickly for traditional security models, exposing enterprise data to unforeseen downstream risks.
A new trade secrets lawsuit against OpenAI creates potential delays for the company's hardware ambitions and upcoming IPO.
Researchers report that critical security flaws in the Claude Chrome extension remain unpatched despite prior vulnerability disclosures.
Threat actors are weaponizing legitimate security software updates to infiltrate high-value government and private sector networks.